CISSP · Free practice question 6 of 12
Role-based access control by job function
Ashbury Hospital has thousands of staff whose system permissions depend on their job, such as nurse, pharmacist or billing clerk, and people change jobs often. The identity manager wants permissions assigned to job functions instead of to individuals. Which model should be implemented?
- A.Discretionary access control
- B.Mandatory access control
- C.Identity-based access control lists on each file
- D.Role-based access control
Show answer and explanation
Correct answer: D. Role-based access control
Why: Role-based access control assigns permissions to roles that represent job functions and then assigns users to roles, so a job change means moving the person to a different role rather than editing many individual permissions. Discretionary access control leaves decisions to data owners, mandatory access control relies on labels and clearances, and per-file identity ACLs are exactly the individual-level management the hospital wants to avoid.
More free CISSP questions
- Senior management ultimate security accountability
- Wassenaar Arrangement export of cryptography
- Brewer-Nash model prevents conflicts of interest
- Known-plaintext cryptanalytic attack
- Air-gapped network physical segmentation
- Misuse case testing of abuse scenarios
- Breach and attack simulation platforms
- Proactive hypothesis-driven threat hunting
- Lessons learned after incident closure
- Access control vestibule stops tailgating
- Cold site characteristics and recovery time